Impact
The vulnerability is an integer overflow or wraparound that can lead to a buffer overflow in Microsoft Office. An attacker who is able to supply malicious content can cause the Office application to execute arbitrary code locally. This local code execution could give the attacker the same privileges as the user, potentially allowing a full system compromise in an enterprise setting.
Affected Systems
The affected products are Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021 and Microsoft Office LTSC for Mac 2024. The specific affected versions are not listed in the advisory, but all releases represented by the provided CPEs are subject to the vulnerability.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity risk, and while the EPSS score is not available, the absence of this metric does not diminish the potential danger. The vulnerability is not yet listed in the CISA KEV catalog, so no publicly known exploits are reported. Because the flaw requires local user interaction to supply a crafted document, the attack is most effective in phishing or social‑engineering scenarios, but once triggered it allows the attacker to run arbitrary code with the user's privileges and may lead to privilege escalation if the user belongs to a privileged group.
OpenCVE Enrichment